Skip to content
Palo Alto Scanning Surges 40X in 24 Hours, Marking 90

Palo Alto Scanning Surges 40X in 24 Hours, Marking 90

Greynoise November 19, 2025

GreyNoise has identified a significant escalation in malicious activity targeting Palo Alto Networks GlobalProtect portals . Beginning on 14 November 2025 , activity rapidly intensified, culminating in a 40x surge within 24 hours , marking a new 90-day high .

GreyNoise has also identified strong connections between this spike and prior related campaigns. We assess with high confidence that these campaigns are at least partially driven by the same threat actor(s), supported by:

Defenders can use GreyNoise Block to immediately block malicious IPs associated with this activity. GreyNoise Block is a fast and easy solution that includes an out-of-box blocklist tracking malicious IPs targeting Palo Alto Networks systems. for ‘Palo Alto’ in the Template Box. You will need to add ‘classification:suspicious’ to block the IPs we are seeing associated with this scanning activity. You can also modify the template to specify source country, other IP classifications, etc. New users can get started with a 14-day free trial.

For GreyNoise customers who need a more targeted blocklist (specifying ASNs, JA4, destination country, etc), GreyNoise now supports full query-based blocklists leveraging the entirety of GreyNoise query parameters.

Since 11/14/2025 , GreyNoise has observed 2.3 million sessions targeting the /global-protect/login.esp URI of Palo Alto PAN-OS and Palo Alto GlobalProtect.

The campaign demonstrates a strong reliance on AS200373 (3xK Tech GmbH) , expressed through two distinct geolocation clusters:

The remaining traffic was primarily sourced from AS208885 (Noyobzoda Faridduni Saidilhom) , forming a secondary but consistent contributor.

For hunting, two JA4t fingerprints encompass all related activity:

The campaign’s infrastructure remains anchored in AS200373 , with German-sourced traffic forming the most substantial segment. The parallel presence of a Canadian geolocation cluster within the same ASN—alongside persistent traffic from AS208885 —indicates a distributed but coordinated hosting footprint.

GreyNoise research has consistently documented a strong historical pattern:

First identified in July, this trend continues to offer meaningful historical context for interpreting the current escalation in Palo Alto–focused activity.

Extracted Entities

Companies (1)

Platforms (2)